Earlier quoted context omitted.
This technically exists but can you actually use it? It seems like there are no articles about it in the 2024 calendar year. I remember reading a really nice screed from walmart last year pushing the fed to turn the screws on rent seekers, but without RFP and ubiquitous participation that isnt going to come about. bit of a conspiracy here but IMO banks have been observing the fraud rates with zelle, venmo, etc and on…
In cases of unauthorized Zelle payments, consumers have legal rights and protections under the Electronic Funds Transfer Act (also known as "Reg E”). This also applies to FedNow instant payments, which has fraud management services available and includes a closed loop reporting requirement. You should expect to see instant payment functionality that runs on FedNow rails within banking apps in the next 6-12 months. I…
Evolve Bank and Trust confirms LockBit stole 7.6M people's data
61–70 of 83 posts
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#62Not saying that this breach is somehow connected, but all of my Wise cards(both physical and virtual) got charged($10, $100, $500) at random locations of the globe in May & June and method was manual entry. While some charges were declined initially because the expiry date was entered wrong on first try(all of my cards coincidentally have expiry date like 04/24 or similar) but cvv was always correct. To make matters…
> cvv was always correct How do you know this, does Wise provide auth response data? (Merchants are not required to respect the CVV check, so it's possible for txns to go through with a non-matching CVV response code.) I'm also curious about the lack of notifications. That would seem to indicate a level of account control beyond the cardholder data. Unless they were failed due to NSF before the notification step.
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#63Earlier quoted context omitted.
> cvv was always correct How do you know this, does Wise provide auth response data? (Merchants are not required to respect the CVV check, so it's possible for txns to go through with a non-matching CVV response code.) I'm also curious about the lack of notifications. That would seem to indicate a level of account control beyond the cardholder data. Unless they were failed due to NSF before the notification step.
what is the point of the CVV if it is not mandatory?
In other cases I've seen the lack of CVV entry result in my card provider triggering a curious 2fa-esque flow with my card provider (I can't remember the name for it) or in other cases, the card provider can just nope out. (Or trigger a fraud alert)
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#64Earlier quoted context omitted.
> cvv was always correct How do you know this, does Wise provide auth response data? (Merchants are not required to respect the CVV check, so it's possible for txns to go through with a non-matching CVV response code.) I'm also curious about the lack of notifications. That would seem to indicate a level of account control beyond the cardholder data. Unless they were failed due to NSF before the notification step.
what is the point of the CVV if it is not mandatory?
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#65Earlier quoted context omitted.
what is the point of the CVV if it is not mandatory?
In some cases a CVV can still result in a cheaper rate for the merchant on the transaction. In other cases I've seen the lack of CVV entry result in my card provider triggering a curious 2fa-esque flow with my card provider (I can't remember the name for it) or in other cases, the card provider can just nope out. (Or trigger a fraud alert)
Probably 3-D Secure / Verified by Visa / etc.
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#66Earlier quoted context omitted.
(1) is absolutely true. (2) - well, it isn’t that hard to become a bank, but it is hard to become a bank when your business plan is “we want to operate well outside of established regulation and norms”. (Starting a state chartered bank is particularly straightforward.) There are many small banks that would like to be acquired and they are generally profitable. A VC-funded fintech would not have a terribly difficult t…
Currently working at a state chartered credit union. Although it is "easy" to start one, most states regulations are very strict and lag significantly behind federal ones. Hell, where I work we aren't even allowed to serve businesses, loans, deposits, or otherwise.
Also not a viable option for a Fintech which aspires to having customers in all 56 US states and territories.
You really need a national bank for a sponsor, and Evolve was the most startup-friendly, for many years.
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#67Freeze your cards! I've posted an Ask HN for better visibility: https://news.ycombinator.com/item?id=40923028
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#68Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#69Not saying that this breach is somehow connected, but all of my Wise cards(both physical and virtual) got charged($10, $100, $500) at random locations of the globe in May & June and method was manual entry. While some charges were declined initially because the expiry date was entered wrong on first try(all of my cards coincidentally have expiry date like 04/24 or similar) but cvv was always correct. To make matters…
> cvv was always correct How do you know this, does Wise provide auth response data? (Merchants are not required to respect the CVV check, so it's possible for txns to go through with a non-matching CVV response code.) I'm also curious about the lack of notifications. That would seem to indicate a level of account control beyond the cardholder data. Unless they were failed due to NSF before the notification step.
Usually, for each transaction, wise gives a small type details, such as
* manual entry: when I manually type in all details on a form
* saved-detail: when I preauthorized some vendor or processor to perform txn without further interactions(think quick checkout using paypal)
* apple/google pay: when card is preauthorized in such
* chip and pin: means I entered the card physically on a machine and entered PIN
* contactless: means an NFC tap pay directly
Usually, all manual entry raises a notification and all the fraud charges were manual entry minus the notifications(immensely unusual unless I used the card with that vendor before frequently) on very random places in matter of days(one in California, followed by one in Tokyo). Then next time two in India followed by one in Vietnam. Then next week two in Malaysia followed by one in Bulgaria. And then several more.
While I freaked out because these vendors were entirely unknown to me and my card were all frozen with no funds in balance, the lack of notification and the charges in pattern(first $10, followed by $100 and then $500 or $250) were very odd.
Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data
#70Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?
> but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank. Because major banks won't support startups looking to compete with them. Why would JPM, BoA, etc. service Mercury who is going after their SMB business banking vertical? Banking is a cartel in the US. The bank lobby makes it as hard as possible to compete with them.
US has more banks than any other country by a factor of 10.
https://www.helgilibrary.com/charts/what-country-has-the-mos...
And #4 for branches per capita: https://www.theglobaleconomy.com/rankings/bank_branches/
7x as many branches per person as Canada
Sure, those data sources are a bit sus, but I'm sure they're relatively correct. And dunno how credit unions play into it.